Got it

2 times NAT

Created: Aug 31, 2021 06:31:11Latest reply: Aug 31, 2021 16:24:12 345 7 0 0 0
  HiCoins as reward: 0 (problem unresolved)

Hi all


I had a pair og USG6716 , also come along with secomanager.


As can seen on the attached topology, it is mandate to do NAT policy on secomanager.


I would like to ask


question 1: As bubble 1 showing, how traffic from DMZ can SSH to the real machine? (USG doing NAT)


question 2: inside host would like to publish over public network, but the firewall facing internet is not the USG, yet traffic is USG (NAT) then another Firewall (NAT again?)


How do i solve this secomanager mandata NAT policy case?

Attachment: You need to log in to download or view. No account? Register

All Answers
DDSN
DDSN Admin Created Aug 31, 2021 06:37:36

Hi noel_nyk,
Please wait a moment. The attachment you uploaded is being scanned. We will reply to you as soon as we see it.
View more
  • x
  • convention:

Hello,
question 1: As bubble 1 showing, how traffic from DMZ can SSH to the real machine? (USG doing NAT)
====== Will the traffic between the Jumphost and the inside host be NATed?

question 2: inside host would like to publish over public network, but the firewall facing internet is not the USG, yet traffic is USG (NAT) then another Firewall (NAT again?)
====== Will the traffic from the inside host be NATed on both inside firewall and outside firewall?
View more
  • x
  • convention:

smileymind
smileymind Created Aug 31, 2021 16:25:36 (0) (0)
 
noel_nyk
noel_nyk Created Sep 1, 2021 01:10:06 (0) (0)
Hi

Jumpshot and inside host passing thru the USG, there force to do the NAT. But i found out secomanage there's an option for NAT policy is no action on source and destination , so this should be ease off the NAT purpose, by using pure routing then.

Is my concept correct?  
chenhui
chenhui Reply noel_nyk  Created Sep 1, 2021 09:14:53 (1) (0)
Yes, no action will not NAT the defined traffic. You can exclude this management traffic from NAT so that you can easily manage your network.  
hemin88
hemin88 Created Sep 3, 2021 11:54:56 (0) (0)
Great answer as usual, well done dear  
Thank
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.